Re: KASAN: use-after-free Read in nf_ct_deliver_cached_events

From: Florian Westphal
Date: Fri Oct 25 2019 - 02:12:01 EST


syzbot <syzbot+c7aabc9fe93e7f3637ba@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
> syzbot has bisected this bug to:
>
> commit 2341e0775747864b684abe8627f3d45b167f2940
> Author: David Howells <dhowells@xxxxxxxxxx>
> Date: Thu Jun 9 22:02:51 2016 +0000
>
> rxrpc: Simplify connect() implementation and simplify sendmsg() op
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=12f869df600000

Looks like 5.2 and earlier crash with a different backtrace than
original.

Proposed patch for this netfilter splat is:
https://patchwork.ozlabs.org/patch/1181533/